Port 123, UDP



  • I'm a newbie to pfSense, I got the VM image to test it out, and its very cool. Set up snort and tested the different VPN's, but I have one question that i cant seem to find an answer for, there's weird traffic coming from the pfSense. Im seeing UDP traffic on port 123 connecting to servers:

    178.63.101.9
    95.130.9.63
    85.236.42.140

    I did some digging and from what i found this could lead to a NTP vulnerability. am i wrong or is this something everyone is aware of?

    I apologise for any ignorance on my part if this turns out to be something simple.



  • That's the system syncing its time, just like Windows, OS X, pretty much every OS in existence today does. Any related vulnerabilities would be with a server not client most always.


Log in to reply